TF-MAL-elf.ebury
📛 Threat Title
Malware family: Ebury
Description
ThreatFox malware family `elf.ebury`. Printable name: Ebury.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.ebury
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ebury
IOC database
- Type
- domain
- Value
elf.ebury- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.ebury
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ebury
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:malpedia.caad.fkie.fraunhofer.de
This payload has been used to compromise kernel.org back in August of 2011 and has hit cPanel Support which in turn, has infected quite a few cPanel servers. It is a credential stealing payload which steals SSH keys, passwords, and potentially other credentials. This family is part of a wider range of tools which are described in detail in the operation windigo whitepaper by ESET.
-
web:thehackernews.com
Ebury malware botnet has compromised an estimated 400,000 servers since 2009. Learn how to protect your systems from this advanced threat.
-
web:web-assets.esetstatic.com
Ebury is alive but unseen: 400k Linux servers compromised for crypto theft and financial gain One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to credit card and cryptocurrency theft. Ten years ago, ESET published
-
web:www.bleepingcomputer.com
A malware botnet known as 'Ebury' has infected almost 400,000 Linux servers since 2009, with roughly 100,000 still compromised as of late 2023.
-
web:www.cioandleader.com
In many cases, Ebury operators were able to gain full access to large servers of ISPs and well-known hosting providers. Ten years ago, ESET published a white paper about Operation Windigo, which uses multiple malware families working in combination, with the Ebury malware family at its core.
-
web:www.eset.com
In many cases, Ebury operators were able to gain full access to large servers of ISPs and well-known hosting providers. Ten years ago, ESET published a white paper about Operation Windigo, which uses multiple malware families working in combination, with the Ebury malware family at its core.
-
web:www.esetngblog.com
One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft.Ten years ago we raised awareness of Ebury by publishing a white paper we called Operation Windigo, which documented a campaign that leveraged Linux malware for financial gain. Today we publish a ...
-
web:www.mphasis.com
Summary A malware botnet known as 'Ebury' has infected almost 400,000 Linux servers since 2009, with roughly 100,000 still compromised as of late 2023.ESET researchers have been following the financially motivated malware operation for over a decade now, warning about significant updates in the payload's capabilities in 2014 and again in 2017.
-
web:www.prnewswire.com
ESET Research has released its deep-dive investigation into one of the most advanced server-side malware campaigns, which is still growing - Ebury group with their malware and botnet.
-
web:www.welivesecurity.com
Figure 5. Multiple malware families deployed on Ebury -infested servers and the impact for potential victims Hiding deeper The Ebury malware family itself has also been updated.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.